LiveActive security incident?Get immediate response
CVE archive

2023 CVE Archive

Browse CVE records published in 2023 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 30600 matching CVEs · Page 7 of 612.

Critical · CVSS 9.8

CVE-2023-29863: Medical Systems Co.

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

Published May 11, 2023 · Updated Jul 5, 2026

High · CVSS 8.9

CVE-2023-36998: The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based...

The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Number List value to the MME to overwrite the stack with arbitrary bytes. An attacker with a cellphone connection to any base station managed by the MME may exploit this vulnerability without having to authenticate with the LTE core.

Published Jan 22, 2025 · Updated Jul 5, 2026

Unknown · CVSS Not scored

CVE-2023-33412: The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (...

The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.

Published Dec 7, 2023 · Updated Jul 5, 2026

Unknown · CVSS Not scored

CVE-2023-33411: A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC)...

A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.

Published Dec 7, 2023 · Updated Jul 5, 2026

Unknown · CVSS Not scored

CVE-2023-31824: An issue found in DERICIA Co.

An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function.

Published Jul 13, 2023 · Updated Jul 5, 2026

Unknown · CVSS Not scored

CVE-2023-31821: An issue found in ALBIS Co.

An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.

Published Jul 13, 2023 · Updated Jul 5, 2026

Unknown · CVSS Not scored

CVE-2023-31819: An issue found in KEISEI STORE Co, Ltd.

An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

Published Jul 13, 2023 · Updated Jul 5, 2026

Unknown · CVSS Not scored

CVE-2023-31868: Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS).

Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. The major one requires the user to be authenticated with a common account, he can then target an Administrator. All others endpoints need the malicious user to be authenticated as an Administrator. Therefore, the impact is diminished.

Published Jun 22, 2023 · Updated Jul 5, 2026

High · CVSS 7.2

CVE-2023-31742: There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006.

There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.

Published May 22, 2023 · Updated Jul 5, 2026

High · CVSS 7.2

CVE-2023-31741: There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06.

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.

Published May 23, 2023 · Updated Jul 5, 2026